Solving the Closest Vector Problem in Time--- The Discrete Gaussian Strikes Again!
arXiv:1504.01995
Abstract
We give a -time and space randomized algorithm for solving the exact Closest Vector Problem (CVP) on -dimensional Euclidean lattices. This improves on the previous fastest algorithm, the deterministic -time and -space algorithm of Micciancio and Voulgaris. We achieve our main result in three steps. First, we show how to modify the sampling algorithm from [ADRS15] to solve the problem of discrete Gaussian sampling over lattice shifts, , with very low parameters. While the actual algorithm is a natural generalization of [ADRS15], the analysis uses substantial new ideas. This yields a -time algorithm for approximate CVP for any approximation factor . Second, we show that the approximate closest vectors to a target vector can be grouped into "lower-dimensional clusters," and we use this to obtain a recursive reduction from exact CVP to a variant of approximate CVP that "behaves well with these clusters." Third, we show that our discrete Gaussian sampling algorithm can be used to solve this variant of approximate CVP. The analysis depends crucially on some new properties of the discrete Gaussian distribution and approximate closest vectors, which might be of independent interest.
References in corpus (3)
Cited by in corpus (4)
- Solving the Shortest Vector Problem in Time via Discrete Gaussian Sampling
- Search-to-Decision Reductions for Lattice Problems with Approximation Factors (Slightly) Greater Than One
- A Note on the Concrete Hardness of the Shortest Independent Vectors Problem in Lattices
- Space-efficient classical and quantum algorithms for the shortest vector problem